Cybersecurity Operations Intern

Ernst & Young Advisory Services Sdn Bhd

Warszawa

Hybrid

PLN 20,000 - 29,000

Part time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible working hours
Hybrid or remote work options
Exposure to enterprise cybersecurity工具

Job summary

EY Poland is offering a CyberSecurity Operations Internship within the Cybersecurity Operations Team. You will gain hands-on experience in monitoring, threat detection, incident response, and vulnerability management across hybrid and remote setups.

You will work with SOC analysts, threat hunters, detection engineers, and vulnerability specialists on real projects, building automation, dashboards, and playbooks while expanding your security skill set.

Qualifications

  • Foundational knowledge of cybersecurity concepts and threat types.
  • Familiarity with SIEM / SOAR / EDR tools and vulnerability management concepts.
  • Analytical thinking and problem-solving mindset.
  • Knowledge of Linux and Windows logs, processes and OS internals.
  • Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S).
  • Interest or experience in Python, PowerShell, Bash and REST APIs.
  • Willingness to develop in IT security.

Responsibilities

  • Support monitoring, detection, and response efforts across SOC and vulnerability management.
  • Assist in triage, investigation and remediation of security incidents.
  • Help design and tune detection content and playbooks.
  • Build dashboards and reports for technical teams and management.
  • Collaborate with SOC analysts, threat hunters, and vulnerability specialists.
  • Participate in projects focused on operationalization of security tools.

Skills

Cybersecurity basics
English & Polish
Linux/Windows knowledge
Networking fundamentals
Threat detection
Scripting basics
Analytical thinking

Education

Student/Graduate of Cybersecurity or related

Tools

CrowdStrike Falcon EDR
CrowdStrike NG-SIEM
Splunk
Microsoft Sentinel
LogScale

Job description

Cybersecurity Operations Team – created as part of the EY Cybersecurity practice in Poland, provides services in the field of security monitoring, threat detection and response, and vulnerability management, with particular focus on the SOC and Vulnerability Management space across on-premises, public and private cloud, and hybrid environments. The team is also responsible for the ongoing operation and optimization of security monitoring and vulnerability management processes for clients across various industries.

The team works on complex, international projects, helping organizations detect, investigate, and respond to threats while continuously identifying and reducing their exposure by embedding security operations capabilities into their environments and engineering workflows. Due to the dynamic growth of these services, we are looking for ambitious individuals to join the team as a CyberSecurity Operations Intern.

Opportunities that await you:

As a CyberSecurity Operations Intern, you will actively support internal security initiatives and client projects focused on monitoring, detecting, and responding to threats, as well as identifying and managing vulnerabilities across modern IT environments. You will gain hands‑on experience with security operations tooling and learn how threats are detected, investigated, and remediated across SOC and Vulnerability Management functions.

You will work closely with SOC analysts, threat hunters, detection engineers, and vulnerability management specialists, learning how to translate security signals and intelligence into practical, automated, and scalable detection and response capabilities.

As a member of the Cybersecurity Operations team, you will take part in many different, interesting projects, mainly related to the design/implementation/operation of security monitoring, threat detection and response capabilities, with a focus on Vulnerability Management and SOC functions (Incident Handling, Threat Hunting, Threat Intelligence, Detection Engineering), including:

  • Supporting the Vulnerability Management lifecycle (asset discovery, vulnerability scanning, prioritization, remediation tracking and reporting)
  • Operating and maintaining vulnerability scanning tools and integrating them with asset inventory and CMDB data
  • Building Vulnerability Management dashboards, metrics and reporting for technical teams and management
  • Assisting in security incident handling and response, including triage, investigation, containment and post‑incident activities
  • Monitoring security alerts and events across SIEM, EDR and other security tooling as an L1/L2 analyst, performing initial triage, validation and prioritization
  • Investigating and escalating confirmed incidents according to defined playbooks and SLAs, documenting findings and supporting containment and remediation actions
  • Helping design, develop and tune detection content (e.g. SIEM/EDR rules, correlation logic, use cases) as part of Detection Engineering
  • Working on end‑to‑end SOC use case development with field experts
  • Helping integrate and automate security tooling via APIs and scripting (e.g. using Python, PowerShell, REST APIs, SOAR playbooks)

Moreover, you will take part in projects focused on the operationalization of CyberSecurity tools such as SIEM / SOAR / EDR and transformation initiatives, which will include tasks such as:

  • SOC - daily monitoring, incident detection and response, reporting, and participation in continuous improvement of monitoring capabilities
  • Engineering - performing regular updates, maintaining automation scripts, system health checks, supporting platform transformations, and maintaining documentation of security systems
  • SOAR - developing and supporting automation workflows, optimizing routine processes, and contributing to incident response efficiency
  • Vulnerability Management - conducting continuous scanning, tracking remediation progress, coordinating with system owners, and improving vulnerability management processes
  • Cloud Security - performing compliance checks, monitoring security issues, implementing best practices, and cooperating closely with the cloud operations team
Skills you will use:
  • Basic understanding of cybersecurity concepts, common attack types, and the CIA triad
  • General knowledge of SIEM / SOAR / EDR tools
  • General knowledge of Vulnerability Management tools and concepts (e.g. Tenable, Qualys, Rapid7) and CVSS‑based risk scoring
  • Analytical thinking and problem‑solving mindset
  • Knowledge of Linux (e.g. RedHat) and Windows including logs, processes and OS internals
  • Understanding of networking fundamentals (TCP/IP, DNS, HTTP/S, ports and protocols)
  • Very good knowledge of English and Polish
  • Student/Graduate of Cybersecurity or related fields (IT profile)
We will also appreciate:
  • Familiarity with alert triage, incident handling and escalation workflows (runbooks/playbooks)
  • Basic familiarity with security tools such as CrowdStrike Falcon EDR, CrowdStrike NG‑SIEM, LogScale, Splunk, Microsoft Sentinel
  • Basic familiarity with VM or security tools such as Tenable, Qualys, Wiz, Rapid7, CrowdStrike, or ServiceNow VR
  • Experience or interest in Python, PowerShell, Bash and REST APIs
  • Possession of industry certificates in the field of IT security, e.g. CompTIA Security+, certification of leading IT/Security solution providers (also in the areas of security of cloud platforms, e.g. Microsoft AZ‑900)
  • Willingness to develop in the area of IT security
You are a good fit for us if:

You are a proactive, well‑organized person who is genuinely passionate about cybersecurity, follows the latest threats, attack techniques, and industry trends, and wants to develop towards Security Operations, threat detection and response, and vulnerability management. You enjoy investigating how attacks work, are curious about technology and automation, and are ready to take on challenges in international, engineering‑driven projects.

We offer:

Interesting work in an international consulting company,

  • Flexible working hours to fit your university schedule
  • Hybrid or remote work options, depending on project requirements
  • Exposure to a wide range of technologies and projects, allowing you to explore different areas of cybersecurity and find your own career path
  • Participation in complex, international projects in the field of implementation of cybersecurity solutions and thus enabling the acquisition of various experiences,
  • Opportunity to gain hands‑on experience with enterprise‑level cybersecurity tools and technologies
  • Personalized programs of courses and trainings,
About EY Poland

We are a global consulting company – we help entrepreneurs, organizations and communities get the most out of their potential. We carry out projects in the field of: Audit, Tax, Transaction and Business Consulting (including IT).

We employ more than 240,000 exceptional people in more than 150 countries around the world. There are over 2800 of us in Poland, and we work in: Warsaw, Gdańsk, Katowice, Kraków, Łódź, Poznań and Wrocław.

We create amazing things together every day. We have people, a development path and training, thanks to which you can also handle the most prestigious projects.

EY is an equal opportunity employer, we appreciate the diversity of knowledge and experience of our employees.

EY provides all candidates with equal opportunities in the recruitment process, regardless of gender, age, race, religion, sexual orientation, national origin, disability or any other legally protected data, in accordance with applicable law.

EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Hybrid/remote work options
Professional development programs
EY Badges and MBA pathway
Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY • Województwo pomorskie

Hybrid
PLN 180,000 - 240,000
Hybrid work arrangements
Professional development programs
EY Badges and MBA pathway
+2
Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY • Warszawa

Hybrid
PLN 180,000 - 280,000
Hybrid work options
Professional development programs
Healthcare & life insurance
+1
Cybersecurity Operations Consultant
Cybersecurity Operations Consultant

EY • Katowice

Hybrid
PLN 120,000 - 180,000
Hybrid/Remote work options
Professional development
EY Badges
+1
Security Engineer EDR
Security Engineer EDR

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
EY Badges
Hybrid/Remote options
Private healthcare and insurance
+2
SIEM/ SOAR Engineer
SIEM/ SOAR Engineer

Ernst & Young Advisory Services Sdn Bhd • Warszawa

Hybrid
PLN 180,000 - 260,000
Hybrid/Remote work
EY Badges
Career Counselor
+3
Security Engineer EDR
Security Engineer EDR

EY • Poznań

Hybrid
PLN 180,000 - 260,000
Flexible working model
Hybrid and remote work options
EY Badges and professional development
+1
Security Engineer EDR
Security Engineer EDR

EY • Łódź

Hybrid
PLN 180,000 - 280,000
Flexible work model
Private healthcare
Life insurance
+2
Security Engineer EDR
Security Engineer EDR

EY • Rzeszów

Hybrid
PLN 140,000 - 210,000
Hybrid and remote work options
EY Badges
Career Counselor
+1
Security Engineer EDR
Security Engineer EDR

EY • Wrocław

Hybrid
PLN 180,000 - 240,000
Hybrid/Remote options
EY Badges
Career Counselor
+1